Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38283 risultati

News
Microsoft komt met noodpatch voor kritiek lek in ASP.NET Core

Microsoft komt met noodpatch voor kritiek lek in ASP.NET Core Microsoft heeft een noodpatch uitgebracht voor een kritieke kwetsbaarheid (CVE-2026-40372) in ASP.NET Core waardoor een ongeauthenticeerde aanvaller via het netwerk SYSTEM-rechten kan krijgen. Het bev ... Read more Published Date: Apr 22, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-40372

CVEfeed Newsroom22 apr 2026
VulnerabilitàAlta
CVE-2026-6848 - Quay: red hat quay: authentication bypass allows privileged actions without valid credentials

CVE ID :CVE-2026-6848 Published : April 22, 2026, 10:16 a.m. | 3 hours, 51 minutes ago Description :A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as token generation or robot account creation, the re-authentication prompt can be bypassed. This allows a user with a timed-out session, or an attacker with access to an idle authenticated browser session, to perform privileged actions without providing valid credentials. The vulnerability enables unauthorized execution of sensitive operations despite the user interface displaying an error for invalid credentials. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-33601 - Insufficient validation of zonemd record

CVE ID :CVE-2026-33601 Published : April 22, 2026, 10:16 a.m. | 3 hours, 51 minutes ago Description :If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Severity: 4.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-33261 - Null pointer accces in aggressive NSEC(3) cache

CVE ID :CVE-2026-33261 Published : April 22, 2026, 10:16 a.m. | 3 hours, 51 minutes ago Description :A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-33262 - Insufficient validation of cookie reply

CVE ID :CVE-2026-33262 Published : April 22, 2026, 10:16 a.m. | 3 hours, 51 minutes ago Description :An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Cookies are disabled by default. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-33259 - Concurrent modification of RPZ data can lead to denial of servce

CVE ID :CVE-2026-33259 Published : April 22, 2026, 10:16 a.m. | 3 hours, 51 minutes ago Description :Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the recursor. Normally concurrent transfers of the same RPZ zone can only occur with a malfunctioning RPZ provider. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-33260 - Insufficient input validation of internal webserver

CVE ID :CVE-2026-33260 Published : April 22, 2026, 10:16 a.m. | 3 hours, 51 minutes ago Description :An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-33257 - Insufficient input validation of internal webserver

CVE ID :CVE-2026-33257 Published : April 22, 2026, 10:16 a.m. | 3 hours, 51 minutes ago Description :An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-33256 - Unbounded memory allocation by internal web server

CVE ID :CVE-2026-33256 Published : April 22, 2026, 10:16 a.m. | 3 hours, 51 minutes ago Description :An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-33258 - Crafted zones can cause increased resource usage

CVE ID :CVE-2026-33258 Published : April 22, 2026, 10:16 a.m. | 3 hours, 51 minutes ago Description :By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3) caches. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-33600 - Null pointer dereference in RPZ transfer

CVE ID :CVE-2026-33600 Published : April 22, 2026, 10:16 a.m. | 3 hours, 51 minutes ago Description :An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Severity: 4.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
News
Critical Atlassian Bamboo Data Center and Server Flaw Enables Command Injection Attacks

Critical Atlassian Bamboo Data Center and Server Flaw Enables Command Injection Attacks Atlassian has disclosed two significant security vulnerabilities affecting its Bamboo Data Center and Server product, including a critical OS command injection flaw and a high-severity denial-of-servi ... Read more Published Date: Apr 22, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-21571 CVE-2026-33871

CVEfeed Newsroom22 apr 2026

Pagina 2139 di 3191

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.